prospect-research-compiler

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize data from untrusted external sources, which creates a surface for indirect prompt injection.
  • Ingestion points: Aggregates intelligence from news, social media, company websites, and financial data as described in the instructions (SKILL.md).
  • Boundary markers: The instructions lack explicit delimiters or "ignore instructions" warnings when processing these external inputs.
  • Capability inventory: The skill aggregates and compiles research, implying the use of search or web-retrieval tools to access the referenced external sources.
  • Sanitization: There is no mention of sanitizing, filtering, or escaping content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:02 PM
Security Audit — agent-trust-hub — prospect-research-compiler